I have spent most of my career in security and platform engineering. The teams that work well are never the ones with the strictest bosses. They are the ones where people close to the problem can actually decide things.
A while ago I went down a rabbit hole reading about how modern military organizations run their operations, and how that compares to normal companies. Not the movie version, with the general shouting orders. The real one. And honestly, the interesting part is not the discipline. It is how much freedom they give to the person on the ground.
These are my reading notes. I kept everything I found useful, with honest notes on what does not translate to a normal company at all.

The hierarchy myth
People assume the military works because of the chain of command. Top orders, bottom executes. That is wrong, at least for the modern NATO-style doctrine. What actually makes it work is a concept called Mission Command, and before that the German idea of Auftragstaktik: the commander states the intent and the desired end state, and the subordinate decides how to get there.
The order is “take that bridge by 18:00”, not “move left, then right, then wait for my call”.
Now compare this to a typical software company. Many companies copy the shape of the hierarchy (approvals, sign-offs, control) without the substance (shared mission, trust, competence at the edge). You get the worst of both worlds: slow decisions and no ownership. In security work I see this constantly. A central team writes policies, the delivery team ignores them, and in the end nobody is really responsible for the risk. The control exists on paper only.
There is also a deeper reason why the two worlds diverge. A military organization is built for environments that are complex, unstable, and hostile, where a wrong decision can be lethal. A company operates in a market that is dynamic, but usually not lethal. The paradox is that modern armed forces are moving towards less vertical structures, betting on professionalism and individual responsibility, while many companies stay stuck in a bureaucratic verticality that kills innovation. The armies are becoming more like good startups, and some companies are becoming more like bad armies.
Mission Command: the real secret
The core of Mission Command is simple to say and hard to do: push authority down, pull risk up. The leader takes the responsibility for failure, and lets the collaborators make the operational decisions.
It works because of trust. Without trust, leaders fall back to micromanagement, they lose the big picture, and the team stops growing. I have seen this exact pattern destroy a security team: every exception needed a signature from three levels up, so people just stopped asking and shipped whatever they wanted. The strict process produced less control, not more.
If you want to apply this in a company, the pillars look like this:
- Unity of effort. Every department understands the common goals and uses shared language and processes.
- Freedom of action. People reach the objectives with the minimum of constraints. You specify only the constraints that are really necessary.
- Mutual trust. Built through transparency and reliability. Leaders accept risk and let the team learn from errors.
- Shared understanding. Honest, continuous dialogue. Everyone knows not only the task, but the deep reason behind it.
- Commander’s intent. Short and memorable. It describes the desired future state, so teams can act on their own even when the situation changes.
What actually makes teams perform
On the civilian side, the best data we have is Google’s Project Aristotle. It started in 2012 inside Google’s People Analytics division, led by Abeer Dubey with Julia Rozovsky (from Yale School of Management) as lead researcher. The name is a tribute to Aristotle: “the whole is greater than the sum of its parts”. They studied around 180 teams for over two years, mixing engineering and sales groups, with surveys and interviews. The starting hypothesis was that the perfect team is about composition: the right mix of skills, seniority, personality. They found no pattern at all. It was not talent. It was not who was in the room.
The number one factor was psychological safety: people can admit a mistake, ask a stupid question, or challenge a decision without being punished for it. The concept itself is older than Google: Amy Edmondson (Harvard) defined it in 1999 in her study of work teams, and she found a beautiful paradox — the best hospital teams reported MORE errors, not fewer. Not because they made more mistakes, but because they talked about them openly. The bad teams hid them. After safety, in order: dependability (people deliver quality work on time), structure and clarity (clear roles, goals, plans), meaning (the work matters personally), and impact (the belief that the work contributes to something bigger).
The things that did not correlate with performance are interesting too: sitting in the same office, consensus-driven decisions, and the individual performance of single “stars”. What mattered were group norms. Two in particular: equality in conversational turn-taking (everyone speaks roughly the same amount of time) and high social sensitivity, measured with the “Reading the Mind in the Eyes” test — basically, the ability to read how the others feel from their expressions.
This matches perfectly with what the military discovered the hard way. The After Action Review exists because after a mission you sit down, leave the rank at the door, and answer four questions: what was supposed to happen, what happened, what went well, what do we change. If the lieutenant cannot admit he made a bad call in front of his squad, the squad repeats the mistake. Same for a post-incident review in a tech company. If the review is a hunt for the guilty, the next outage will last longer.
How a team grows: the Tuckman stages
A team does not become great on day one. The classic model from Bruce Tuckman (stages of group development) describes five phases, and a good leader changes style in each one:
- Forming. Orientation and caution. The team needs a clear vision, specific goals, defined roles.
- Storming. The first conflicts and power struggles appear. This phase is unavoidable, and it is where trust gets built. The leader mediates tensions and keeps the group focused on shared goals.
- Norming. Routines and processes settle. Members accept differences and start to really collaborate. Leadership becomes more shared.
- Performing. The team is autonomous, motivated, functional. The leader delegates and acts as a facilitator.
- Adjourning. The group closes. You evaluate results and celebrate what worked.
Most managers I have met try to skip Storming. It does not work. The conflict comes back later, worse, usually right before a deadline.
The failure modes are always the same
Lencioni’s Five Dysfunctions of a Team reads almost like a description of a broken military unit. It is a pyramid, and it starts from the bottom:
- Absence of trust. Fear of being vulnerable. Without trust, information gets hidden and conflicts get avoided.
- Fear of conflict. The team looks for an artificial harmony. Healthy teams argue about ideas to find the best solution.
- Lack of commitment. If you were not heard in the debate, you do not commit to the decision.
- Avoidance of accountability. Members do not call each other out on standards. The real motivation comes from peer pressure, not only from the boss.
- Inattention to results. People chase personal goals and status instead of the collective result.
I have watched security teams fall into exactly this trap. An engineer finds a real problem in a release, stays quiet because last time he raised a flag he got blamed for the delay, and the vulnerability ships. That is not a technical failure. It is a trust failure, first level of the pyramid.
There is no single right leadership style
The situational leadership model by Hersey and Blanchard says the leader must adapt to the maturity of the collaborator for that specific task:
- Telling (directing): for people with low competence but high motivation. Precise instructions, close supervision.
- Selling (coaching): for people with some competence but dropping motivation. The leader explains the decisions and gives emotional support.
- Participating (supporting): for people with high competence but variable confidence. The leader facilitates and shares the decision process.
- Delegating: for people with high competence and high motivation. The leader gives autonomy and checks only the final result.
The mistake is to use one style for everyone. The junior on their first incident needs Telling. The senior engineer needs Delegating. Use Telling with the senior and they quit. Use Delegating with the junior and they drown.
Transactional vs transformational
Another useful distinction. Transactional leadership is an exchange: rewards for good performance, penalties for bad. It focuses on short-term goals and stability. Transformational leadership inspires people to go beyond their limits, pushing innovation and personal growth. The transformational leader is a role model and builds a culture of belonging and purpose.
Both have a place. Payroll and compliance are transactional. But a security culture, the thing where people report problems early and care about quality when nobody watches, is transformational or it does not exist.
Speed: the OODA loop
One military tool that translates well is the OODA loop: Observe, Orient, Decide, Act. The side that cycles through this loop faster usually wins. But the step everyone skips is “Orient”. That is where your mental models filter the raw data. A team with an outdated model (“more process means more safety”, “hard work always pays off”) will misread clear evidence every single time.
For incident response this is literally the job. Observe the telemetry, orient with the actual architecture (not the diagram from last year), decide, act, loop again.
Flawless Execution
Another framework born from fighter pilots is the Flawless Execution model (developed by Afterburner). It is a cycle of four phases:
- Plan. Define objectives that are clear, measurable, achievable, and that support the global strategy.
- Brief. Communicate the plan so that the people on the front line know exactly what is expected. Misalignment here is the cause of most business failures.
- Execute. Fight “task saturation”, the feeling of having too many things to do without time or resources. As saturation grows, performance collapses.
- Debrief. A “nameless and rankless” session after every mission. What worked, what did not, why, and what we change in the next plan.
Pilots consider the debrief more important than the mission itself. In a company, this is how you turn experience into collective intelligence instead of letting it stay inside one person’s head.
Learning as an organization: AAR and Red Teaming
The After Action Review deserves its own section because it is the main tool for continuous learning. It is not a “post-mortem” (that word alone discourages participation). It is a constructive reflection focused on future improvement. To run a good one:
- Plan. Identify the event to analyze and involve the people closest to it.
- Prepare. Collect objective data (metrics, communication logs) to avoid discussions based on opinions.
- Conduct. Use a neutral facilitator. Answer the four key questions: expectation vs reality, what went well, what to improve.
- Follow up. Turn the findings into actionable recommendations, with a named owner and a deadline. Without this, the AAR is theatre.
And then there is Red Teaming: a “red team” simulates the enemy or the competitor to expose the weak points of a plan before launch. This prevents groupthink and overconfidence. In security this is home turf for me, but the same idea works for a business plan or a product launch: have someone attack the plan before reality does.
Why autonomy works: the psychology under it
There is a scientific reason why Mission Command works so well, and it is the Self-Determination Theory. It says humans have three innate psychological needs for autonomous motivation:
- Autonomy: the feeling that your actions come from your own choice, not external control.
- Competence: the feeling of being effective and able to master the task.
- Relatedness: the feeling of connection and belonging to a group.
Research done in the Norwegian armed forces confirmed that Mission Command-style leadership increases the satisfaction of the need for autonomy, which reduces turnover intentions and increases job satisfaction. On the other side, organizations that abuse incentives and punishments (controlled motivation) get weaker long-term performance and more exhausted people. If you have ever worked somewhere driven by KPI bonuses, you know exactly what this feels like.
Companies that actually did it
This is not only theory. Two examples worth reading:
Bayer redesigned its operating model around Dynamic Shared Ownership: autonomous teams that take 95% of operational decisions, hierarchy cut down from twelve levels to a few, traditional functions rebuilt as customer-oriented micro-enterprises.
Haier, the Chinese appliance giant, went further with the Rendanheyi model: they removed middle managers and turned the company into a network of micro-enterprises that operate like startups, each responsible for its own budget and market strategy.
In these models the leader stops managing daily activities and takes four new roles: visionary (defines a clear mission), architect (designs the systems and the resource flows), catalyst (removes obstacles and frees energy), and coach (builds continuous learning on fast cycles).
The soft skills are the hard part
Last point. Everything above depends on the so-called soft skills, which are actually strategic hard skills. Emotional intelligence lets you read the emotions in the room and stop conflicts before they explode. Active listening (including the non-verbal signals) and assertive feedback (honest but respectful opinions) are the connective tissue that keeps different people working as one unit.
An empathetic leader builds an inclusive culture that attracts talent. A leader who manages conflict with patience and objectivity, separating the problem from the person, keeps the team together when the pressure rises. None of this is optional if you want to delegate real authority.
What to steal and what to leave
My personal summary, after reading all of this:
- Steal: intent-based delegation. Say the “what” and “why”, let the team pick the “how”. In my world this means guardrails and secure defaults, not approval queues.
- Steal: the debrief without rank. A blameless AAR after every incident, with a real follow-up owner and deadline.
- Steal: red teaming. Have someone attack your plan before reality does.
- Steal: adapting your style to the maturity of the person in front of you. One style for everyone manages nobody.
- Leave: command by authority. In a company people are not soldiers, they can just quit. And the good ones do.
- Leave: the idea that structure alone creates performance. Google’s data is clear: it does not.
The military model works not because it is strict, but because at its best it is built on trust, shared mission, and decisions pushed to the person closest to the problem. A company can copy that. But it has to give up bureaucratic control in exchange, and that is the part most managers are not willing to pay.
Sources and further reading: Mission Command and Auftragstaktik (Wikipedia), Project Aristotle (Google rework), Psychological Safety and Learning Behavior in Work Teams (Edmondson, 1999), Five Dysfunctions (Lencioni), Tuckman’s stages, Situational leadership (Hersey-Blanchard), OODA loop, After Action Review, Red team, Self-Determination Theory, Bayer DSO (Peerdom), Haier Rendanheyi (Corporate Rebels).
